UK GDPR and Patient Photographs Sent to an AI Service
Ask most dental practices what their lawful basis is for sending a patient’s intraoral photo to an AI triage tool, and you get the same answer: “We have consent.” It is on the treatment plan. It is in the new patient form. Sometimes it is a tick box in the practice management software that nobody has looked at since 2019.
That answer is usually wrong, and it is wrong in a way that creates more risk than having no answer at all. Consent under UK GDPR is a specific legal instrument with conditions attached, and clinical images processed for care purposes almost never satisfy them. Worse, once you have told a patient their data is processed on the basis of consent, you have handed them a right to withdraw it at any time and you have promised to stop when they do. If your AI vendor has already used that image to improve a model, or your clinical record retention obligation says you must keep it for eleven years, you cannot keep that promise.
This piece works through the actual decision: which lawful basis applies to patient photographs and radiographs sent to an AI service, which special category condition sits alongside it, and what you have to have in place instead of a consent form.
Two locks, not one
UK GDPR requires two separate things for health data, and practices routinely conflate them.
The first is a lawful basis under Article 6. There are six: consent, contract, legal obligation, vital interests, public task, legitimate interests. You need exactly one.
The second is a condition under Article 9, because health data is special category data and Article 9(1) prohibits processing it unless one of ten exemptions applies. A photograph of a patient’s dentition, taken in a clinical setting, for a clinical purpose, is health data. So is a bitewing. So is a photo of a swollen face sent into your triage inbox at 8am.
These are independent locks. Satisfying Article 6 does not satisfy Article 9, and picking “consent” for one does not oblige you to pick it for the other. The Article 9(2)(a) condition is “explicit consent”; the Article 6(1)(a) basis is “consent”. They are different standards with different names, and you can lawfully use Article 6(1)(f) legitimate interests alongside Article 9(2)(h) health care, which is exactly what most practices should be doing and almost none document.
Why consent fails for clinical images
Article 4(11) defines consent as freely given, specific, informed and unambiguous. The ICO’s guidance is blunt about what “freely given” means when there is an imbalance of power between the controller and the data subject.
Consider the practical test. A patient in the chair with a fractured UR1 is asked to tick a box allowing their photograph to go through an AI shade-matching or caries-detection tool. If they decline, does the appointment continue exactly as it would have? Do they get the same clinical pathway? If the honest answer is that declining changes their care, the consent is not freely given and it is not valid consent. If the honest answer is that declining changes nothing, you have to ask why you are relying on a permission you do not need.
Then there is withdrawal. Article 7(3) gives an unconditional right to withdraw consent, and withdrawal must be as easy as giving it. Set that against your retention obligations: adult dental records in England are held for a minimum of 11 years under the Records Management Code of Practice 2021, and for children until their 25th birthday, or 26th if the patient was 17 at the time of treatment. Scotland works to 11 years under NHS Scotland’s code. A radiograph forms part of the clinical record. You cannot delete it because someone withdrew consent, and if you have told them you would, you have made a statement in your privacy notice that is not true.
There is a narrower failure too. Consent must be specific. “We may use AI tools to assist with your care” is not specific to anything. Naming the processor, the purpose and the categories of data is what specificity requires, and a practice using Pearl’s Second Opinion for radiograph reading, Overjet for bone level measurement and a separate front-desk triage tool would need three distinct consents, each individually withdrawable, each tracked. Nobody is running that operation on a Tuesday morning list.
What to rely on instead
For clinical images processed to deliver or support care, the pairing is:
Article 6(1)(e) or 6(1)(f). If you hold an NHS contract, processing for NHS dental care is a public task under 6(1)(e) as a task in the public interest. For private work, or for the private side of a mixed practice, legitimate interests under 6(1)(f) does the job, provided you have completed and retained a legitimate interests assessment. That LIA is not a formality; it is the evidence that you balanced your interest in accurate caries detection against the patient’s interest in not having their data spread further than necessary. Two pages is enough.
Article 9(2)(h). This is the condition for processing necessary for “preventive or occupational medicine… medical diagnosis, the provision of health or social care or treatment”. It applies when processing is done by, or under the responsibility of, a professional subject to a duty of confidentiality. A GDC-registered dentist qualifies. So does the practice, acting under that responsibility. Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018 is the domestic provision that gives it effect, and it requires an appropriate policy document. Most practices do not have one, and it takes about an hour to write.
Note what changes here. Under 9(2)(h), no consent is required and no withdrawal right attaches to the lawful basis. The patient retains their Article 21 right to object where you relied on 6(1)(f), and you must consider it, but you are not committed in advance to deleting a clinical record.
Where consent does still apply
Two genuine cases, and they are narrower than practices assume.
Marketing and case studies. A smile makeover before-and-after on your Instagram is not health care processing. It is promotion. That needs explicit consent under 9(2)(a), freely given, and it must be genuinely separable from the treatment: the patient who says no still gets their composite bonding, and you must be able to show they knew that.
Secondary use for model training. If your vendor’s contract says they may use your patient images to improve their algorithm, that is a purpose outside the care of that patient. Check the DPA. Some vendors are explicit about it. VideaHealth’s UK-facing terms and Pearl’s enterprise agreements both distinguish service provision from product improvement, and the latter typically requires either explicit consent or robust anonymisation. Anonymisation of a full-face clinical photo is not achievable; anonymisation of a bitewing with metadata stripped is arguable but you need the vendor to commit in writing to what “stripped” means.
The transfer question, which is where most practices actually fail
Getting the lawful basis right is necessary and not sufficient. The moment the image leaves your server, Chapter V of UK GDPR applies.
Work through a real configuration. A practice in Leeds uses Pearl Second Opinion inside its Carestream Dental workflow. Pearl is a US company. Radiographs go to US infrastructure for inference. That is a restricted transfer. Lawful routes: the UK Extension to the EU-US Data Privacy Framework, if the vendor is certified and the certification covers this data; or the ICO’s International Data Transfer Agreement; or the EU SCCs plus the UK Addendum. You need to know which one, and you need a Transfer Risk Assessment on file.
Ask the vendor, in writing, and keep the reply:
1. Where is inference performed? Name the region. → e.g. eu-west-2 (London)
2. Where is data at rest? Name the region. → e.g. eu-west-2
3. Sub-processor list and their locations? → current list + 30 days' notice of change
4. DPF certified for HR/non-HR data? Cert number? → or IDTA / SCCs+Addendum
5. Retention period for uploaded images? → e.g. 90 days then deletion
6. Is our data used for model training? Opt-out? → yes/no, and the contract clause number
7. Breach notification window to us? → must support our 72h Art.33 duty
Several tools now offer UK or EU region processing as a configuration option rather than a default. If you do not ask, you get the default. A practice manager who sends those seven questions and files the answers has done more for their compliance position than one who redrafts the consent form.
The DPIA is mandatory here
Article 35 requires a Data Protection Impact Assessment where processing is likely to result in high risk. The ICO’s list of processing operations always requiring a DPIA includes large-scale processing of special category data, use of innovative technology, and biometric data. AI-assisted radiograph reading hits at least two of those on any reading.
A 4,000-patient practice adopting Overjet or Pearl is doing large-scale special category processing with innovative technology. The DPIA is not optional and not retrospective: Article 35(1) says it must be carried out prior to the processing. If you are already live and have no DPIA, do it now and date it honestly rather than backdating it, which is the kind of thing that turns a minor finding into a serious one.
Fines here are not theoretical in the way people assume. The ICO’s approach to health sector cases has leaned toward reprimands over penalties, but reprimands are published, and a CQC inspection that finds a published ICO reprimand on AI processing will read it as a governance failure under the well-led domain. The reputational exposure runs through CQC, not just the ICO. Our broader guidance on regulation and governance covers how those two regimes interact for practices adopting clinical AI.
A worked example, start to finish
Mixed NHS and private practice, three surgeries, 5,200 active patients. Adopting an AI caries detection tool that reads bitewings and periapicals.
Article 6: 6(1)(e) public task for the NHS cohort, 6(1)(f) legitimate interests for the private cohort. One LIA covering the private side, signed by the principal, reviewed annually.
Article 9: 9(2)(h) health care, with the DPA 2018 Schedule 1 Part 1 para 2 appropriate policy document written and retained until six months after the processing ends.
Consent: not used as the lawful basis. Used separately and explicitly for the two case-study photographs going on the website, recorded against those two patients only, with a note that withdrawal removes the images from the site within five working days.
Privacy notice: updated to name the AI processor, state the purpose (assisting the clinician’s interpretation of radiographs), state that the clinician makes the final diagnostic decision, name the transfer mechanism, and state the vendor’s retention period. Roughly 180 words added.
DPIA: completed before go-live, identifying the transfer risk, the risk of automation bias in clinicians over-relying on the tool, and the mitigation that all AI findings are reviewed and either accepted or rejected by the treating dentist with the decision recorded.
Article 22: confirmed not engaged, because there is no solely automated decision with legal or similarly significant effect. A human clinician decides. Document that conclusion; do not just assume it. If you later adopt a triage tool that auto-books or auto-declines appointments without human review, Article 22 does engage and the analysis changes entirely.
None of this takes a solicitor. It takes an afternoon, an honest set of answers from your vendor, and the willingness to stop calling something consent when it is not. The practices that get this wrong are rarely the ones that ignored data protection. They are the ones that did the paperwork enthusiastically, in the wrong box, and now have a privacy notice that promises a deletion they are legally forbidden from performing.